By Fatskills Exam Guides Team — the exam nerds behind 28,500+ quizzes and 2.1M practice questions across 500+ global exams.
Security governance and policies provide the framework, rules, and oversight needed to protect an organization’s information assets. Without them, even the best technical controls (firewalls, encryption) fail due to misalignment with business goals, compliance gaps, or human error.
Real-world example:In 2020, Twitter suffered a high-profile breach where attackers socially engineered employees to gain access to internal admin tools, leading to the hijacking of high-profile accounts (e.g., Barack Obama, Elon Musk). The root cause? Weak governance—no multi-factor authentication (MFA) for admin tools, poor employee training, and unclear policies on access control. The attack cost Twitter $1.1M in fines and reputational damage.
Governance ensures policies are aligned with business objectives, compliant with laws (GDPR, HIPAA), and enforced consistently.
Governance (Security Governance): The oversight and decision-making process that ensures security aligns with business goals. Led by executives (CISO, Board) and supported by frameworks like ISO 27001, NIST CSF, COBIT.
ISO 27001: An international standard for Information Security Management Systems (ISMS). Provides a risk-based approach to security, requiring policies, risk assessments, and continuous improvement (Plan-Do-Check-Act cycle).
NIST Cybersecurity Framework (CSF): A voluntary U.S. framework (developed by NIST) with 5 core functions: Identify, Protect, Detect, Respond, Recover. Used by critical infrastructure (banks, healthcare) but applicable to any organization.
COBIT (Control Objectives for Information and Related Technologies): A governance framework by ISACA that bridges IT and business goals. Focuses on aligning IT with business strategy, risk management, and compliance (e.g., SOX, GDPR).
Policy vs. Standard vs. Procedure vs. Guideline:
Guideline: Recommended best practices (e.g., "Use a password manager").
Risk Management (NIST SP 800-37): The process of identifying, assessing, and mitigating risks to an acceptable level. Includes:
Risk Monitoring (continuous review).
Business Impact Analysis (BIA): A risk assessment method that identifies critical business functions and their maximum tolerable downtime (MTD). Helps prioritize recovery efforts (e.g., "Payroll must be restored within 4 hours").
Data Classification: Labeling data based on sensitivity (e.g., Public, Internal, Confidential, Restricted). Ensures proper handling (e.g., encryption for "Restricted" data).
Compliance vs. Security:
Security: Implementing controls to protect assets, which may go beyond compliance. ⚠️ Exam trap: Compliance ≠ Security (e.g., a company can be HIPAA-compliant but still have weak security).
Security Awareness Training: Educating employees on security policies, phishing, and social engineering. Most breaches start with human error (e.g., clicking a malicious link).
Third-Party Risk Management (TPRM): Assessing and monitoring vendors/suppliers for security risks (e.g., SolarWinds hack via a compromised software update).
Incident Response Plan (IRP): A documented process for detecting, responding to, and recovering from security incidents (NIST SP 800-61).
Assign roles/responsibilities (RACI matrix: Responsible, Accountable, Consulted, Informed).
Conduct a Risk Assessment
Prioritize risks (e.g., "High: Unpatched VPN servers").
Develop Policies & Controls
Example controls:
Implement & Train
Test controls (penetration testing, tabletop exercises).
Monitor & Improve (PDCA Cycle)
Act: Update policies based on findings (e.g., "Add MFA for all remote access").
Compliance & Certification (Optional)
⚠️ Exam trap: "Who is responsible for governance?" → Board of Directors (not the CISO).
ISO 27001 vs. NIST CSF:
COBIT = IT governance (aligns IT with business goals).
Risk Management Questions:
Incident Response Policy: Steps for detecting, responding, and recovering from breaches.
NIST CSF Core Functions:
D) PCI DSS ✅ Correct Answer: C) COBIT Explanation: COBIT is designed to align IT with business goals, while ISO 27001 and NIST CSF focus on security controls, and PCI DSS is for payment card security.
During a risk assessment, a security team identifies that a web server has a vulnerability with a Single Loss Expectancy (SLE) of $50,000 and an Annualized Rate of Occurrence (ARO) of 0.5. What is the Annualized Loss Expectancy (ALE)?
D) $250,000 ✅ Correct Answer: A) $25,000 Explanation: ALE = SLE × ARO → $50,000 × 0.5 = $25,000.
A hospital is implementing a new security policy. Which of the following is an example of a standard (not a policy, procedure, or guideline)?
Good luck on your exam! ?
Join 4M+ learners. Unlock unlimited quizzes, wrong-answer tracking, flashcards + reminders, study guides, and 1-on-1 challenges.